Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Syncope — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in Apache Syncope, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Apache Syncope, an open-source identity and access management platform, primarily focusing on injection, authentication, and authorization weaknesses. The collection includes critical issues such as SQL injection, missing authentication, and privilege escalation flaws reported since the product’s early releases. Users can track vendor security advisories, analyze patterns in vulnerability classes, and review the historical exposure of this identity management tool. The data covers publicly disclosed incidents from 2011 through the present, providing a consolidated view of threats specific to Syncope’s role in directory synchronization and user provisioning. By examining these entries, readers can understand how recurring weaknesses in this product have evolved over time and identify areas requiring remediation in deployed instances.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-73191 Apache Syncope: CAS service URL injection via Forwarded HTTP headers CWE-601 - - 2026-09-14
CVE-2026-73195 Apache Syncope: CSV export spreadsheet formula injection CWE-116 - - 2026-09-14
CVE-2026-73236 Apache Syncope: Cross-Realm authorization bypass in delegated administration CWE-863 - - 2026-09-14
CVE-2026-73370 Apache Syncope: Cross-Realm boundaries reconciliation bypass CWE-863 - - 2026-09-14
CVE-2026-73178 Apache Syncope: JWT Access Token takeover CWE-200 - - 2026-09-14
CVE-2026-73470 Apache Syncope: Delegating users can grant unowned Roles CWE-269 - - 2026-09-14
CVE-2026-73579 Apache Syncope: Non-recursive Any search could skip Realms restrictions CWE-863 - - 2026-09-14
CVE-2026-75015 Apache Syncope: Nested secrets leak cleartext into audit records readable CWE-522 - - 2026-09-14
CVE-2026-75030 Apache Syncope: Incomplete authorization checks for Group members deprovisioning CWE-862 - - 2026-09-14
CVE-2026-77051 Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search CWE-89 - - 2026-09-14
CVE-2026-73668 Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values CWE-863 - - 2026-09-14
CVE-2026-77147 Apache Syncope: Groovy Sandbox escape for empty CommandArgs CWE-94 - - 2026-09-14
CVE-2026-77181 Apache Syncope: ClientApp update entitlement not effective CWE-863 - - 2026-09-14
CVE-2026-77883 Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist CWE-202 - - 2026-09-14
CVE-2026-78318 Apache Syncope: Unauthenticated reflected XSS in Console and Enduser CWE-79 - - 2026-09-14
CVE-2026-78330 Apache Syncope: Privilege escalation for admin user via JWT authentication CWE-266 - - 2026-09-14
CVE-2026-78336 Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user CWE-201 - - 2026-09-14
CVE-2026-82232 Apache Syncope: SQL injection via sort parameter in Task search CWE-89 - - 2026-09-14
CVE-2026-86460 Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence CWE-89 - - 2026-09-14
CVE-2026-87779 Apache Syncope: AES Secret Key disclosure via log output CWE-532 - - 2026-09-14
CVE-2026-87785 Apache Syncope: JWT subject spoofing CWE-290 - - 2026-09-14
CVE-2026-87802 Apache Syncope: SRA OAuth2 JWT signature verification bypass CWE-347 - - 2026-09-14
CVE-2026-62418 Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check CWE-918 - - 2026-07-20
CVE-2026-62183 Apache Syncope: User self-service privilege escalation CWE-269 - - 2026-07-20
CVE-2026-57308 Apache Syncope: SQL injection vulnerability in Audit Events search CWE-89 - - 2026-07-20
CVE-2026-53421 Apache Syncope: Remote Code Execution via Scripted Connector CWE-653 - - 2026-07-20
CVE-2026-53405 Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask CWE-653 - - 2026-07-20
CVE-2026-63071 Apache Syncope: RCE via Groovy Sandbox bypass CWE-653 - - 2026-07-20
CVE-2026-42797 Apache Syncope: JexlContextBuilder Information Disclosure CWE-202 - - 2026-05-25
CVE-2026-42782 Apache Syncope: Post-auth RCE via Groovy static CWE-653 - - 2026-05-25

All 44 known CVE vulnerabilities affecting Apache Syncope with full Chinese analysis, references, and POCs where available.